Privacy Policy
How we collect, use, store, and transfer personal and business data — and the rights you have over it under the GDPR.
Last updated: NEEDS CORRECTION
Template notice. This document is a drafting starting point, not legal advice. Have it reviewed by a qualified Lithuanian lawyer before you rely on it, and replace every highlighted placeholder first.
1. Who we are
This policy is issued by NEEDS CORRECTION, trading as BlueShelf, established in the Republic of Lithuania.
- Registration number: NEEDS CORRECTION
- VAT number: NEEDS CORRECTION
- Registered office: NEEDS CORRECTION
- Data protection contact: hello@blueshelfagency.com
We act as the data controller for data about our own clients and website visitors. Where we operate a client's Walmart Marketplace account on their instructions, we act as a data processor on that client's behalf, under a separate data processing agreement.
2. Data we collect
2.1 Client business information
- Company name, registration and VAT numbers, and registered address
- Contact names, business email addresses, and phone numbers
- Business documents supplied for marketplace onboarding (licences, certificates)
- Product catalogue data, imagery, and listing content
2.2 Billing data
- Invoicing details, billing address, and payment references
- Transaction records required for Lithuanian accounting and tax law
We do not store full payment card numbers. Card payments, where offered, are handled by a third-party payment processor.
2.3 Walmart API and developer credentials
To manage a client account we may be granted Walmart Marketplace developer credentials, API keys, client IDs and secrets, or delegated Seller Center access. These are treated as confidential secrets: stored only in encrypted secret management, never committed to source control, never sent over email or chat in plain text, and revoked on request or at the end of the engagement.
2.4 Website data
- Information you submit through our contact form (name, email, store URL, message)
- Aggregate, cookieless website analytics (page views and referrers only — no cookies, no individual tracking; see §10)
- Server log data such as IP address and user agent, retained for security purposes
3. Why we process it, and on what legal basis
- Account setup and marketplace onboarding — performance of a contract (Art. 6(1)(b) GDPR).
- Listing creation, optimisation, and catalogue management — performance of a contract.
- Advertising and campaign optimisation — performance of a contract.
- Invoicing, accounting, and statutory record keeping — legal obligation (Art. 6(1)(c)).
- Responding to enquiries, securing our systems, and understanding site usage in aggregate — legitimate interests (Art. 6(1)(f)).
4. Who we share data with
We share data only where necessary, with:
- Walmart Inc. and its marketplace systems, to operate your seller account
- Hosting, email delivery, and analytics providers acting as our processors
- Our accountants and professional advisers
- Public authorities where we are legally required to disclose
We do not sell personal data, and we do not share it for third-party advertising.
5. International transfers (EU → US)
Operating a Walmart Marketplace account inherently involves transferring data to the United States. Some of our service providers are also US-based. Where we transfer personal data outside the European Economic Area, we rely on one or more of the following safeguards:
- Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), incorporated into our agreements with the recipient;
- the recipient's certification under an applicable EU–US adequacy framework; or
- a derogation under Article 49 GDPR where strictly necessary.
We carry out a transfer impact assessment where required and apply supplementary technical measures, including encryption in transit and at rest and strict access control. You may request a copy of the relevant safeguards by emailing hello@blueshelfagency.com.
6. How long we keep data
- Contract and client records: for the engagement plus the statutory limitation period.
- Accounting and invoicing records: NEEDS CORRECTION years, as required by Lithuanian law.
- API credentials and access tokens: revoked and deleted at the end of the engagement, or sooner on request.
- Contact form enquiries: up to 24 months from last contact.
- Server and security logs: up to 12 months.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten") where applicable
- Restrict or object to processing
- Export your data in a structured, commonly used, machine-readable format (data portability)
- Withdraw consent at any time, without affecting processing already carried out
- Not be subject to solely automated decision-making with legal effects
To exercise any of these, email hello@blueshelfagency.com. We respond within one month, extendable by two further months for complex requests. There is no charge unless a request is manifestly unfounded or excessive.
8. Complaints
If you believe we have handled your data unlawfully, please contact us first so we can put it right. You also have the right to lodge a complaint with the Valstybinė duomenų apsaugos inspekcija (VDAI), the Lithuanian supervisory authority, at https://vdai.lrv.lt, or with the authority in your country of residence.
9. Security
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, HSTS, encrypted secret storage, least-privilege access to client accounts, and hardened HTTP response headers. No system is perfectly secure, but we notify affected parties and the supervisory authority of qualifying breaches without undue delay and within 72 hours where required.
10. Cookies
This site does not use cookies, tracking pixels, or any similar device-storage technology — not for essential purposes, not for analytics, and not for marketing. Website usage is measured with a cookieless, aggregate analytics tool (Vercel Web Analytics) that does not set cookies, does not use device fingerprinting, and does not collect or store any data that identifies you individually. Because no cookies are used, no cookie consent banner is shown.
11. Changes to this policy
We may update this policy as our services or the law change. The "last updated" date above reflects the current version, and material changes will be communicated to active clients directly.